Johnson & Johnson Careers
MANAGER IT INTERNAL AUDIT CYBERSECURITY
Requisition ID: 4857190121
Johnson & Johnson Corporate Internal Audit is seeking an Audit Manager - Information & Cyber Security The preferred location for this position is New Brunswick, NJ;
Caring for the world, one person at a time has inspired and united the people of Johnson & Johnson for over 130 years. We embrace research and science -- bringing innovative ideas, products and services to advance the health and well-being of people.
With $81.6 billion in 2018 sales, Johnson & Johnson is the world's most comprehensive and broadly-based manufacturer of health care products, as well as a provider of related services, for the consumer, pharmaceutical, and medical devices markets. There are more than 250 Johnson & Johnson operating companies employing over 125,000 people and with products touching the lives of over a billion people every day, throughout the world. If you have the talent and desire to touch the world, Johnson & Johnson has the career opportunities to help make it happen.
Johnson & Johnson Corporate Internal Audit is seeking a Manager IT Internal Audit & Assurance, the preferred location for this position is New Brunswick, NJ.
Corporate Internal Audit's primary mission is to provide independent, objective assurance and advisory services to assist management in maintaining compliance with government and industry regulations, mitigating risk and achieving operational excellence. To this end, the Manager IT Internal Audit & Assurance conducts audits of information resources across the Johnson & Johnson Family of Companies to evaluate the adequacy of internal controls and to develop recommendations for improvement. Information resources include business critical applications such as SAP, JD Edwards, and BPCS, as well as the related technology infrastructure, data, facilities, organizations, and processes.
- Manage IT Audit & Internal Controls Assurance engagements.
- In addition to their audit management responsibilities, IT Internal Audit Managers work closely with-Information Technology Management, Internal Audit leadership, and External Audit to assess risk and update requirements.
- Managers provide leadership and coaching to a subordinate staff of IT audit professionals and Corporate Internal Audit team members. They are also expected to lead internal capability and improvement projects using appropriate methodologies – e.g., System Development Life Cycle, Six Sigma.
- Lead & Perform ongoing risks assessment for their assigned portfolio.
- Advise and perform an ongoing risk assessment of IT security control design.
- Lead internal control reviews & audits of technology domains & capabilities
- Leads development, documentation and maintenance of information technology audit program consistent with enterprise policies, procedures, and established industry standards & methods
- Initiates, facilitates, and promotes activities to create information security audit approach, awareness and training throughout the department.
- Independently assess the design and operating effectiveness of internal controls over financial reporting
- Develop and maintain adequate control and process documentation (i.e. control matrices, flowcharts, testing documentation) in accordance with engagement objectives
- Performs root cause analysis and articulate control deficiencies and remediation techniques both internally and with client senior management
- Support and monitor remediation activities, as and when necessary
- Maintain ongoing awareness of significant changes related to new regulatory compliance pronouncements would not expect this level to be monitoring compliance changes) that result and emerging technologies
- Coordinate and manage interactions with multi-functional and cross-geographical teams both internally and externally, as necessary
- Identifies weaknesses in internal controls and opportunities to enhance operational efficiencies.
- Participating in the development of, and implementing Cybersecurity initiatives including but not limited to policies, strategic projects, activities resulting from internal or external audits
- A Bachelor's degree (BA/BS) is required. A professional security, audit, or control-related certification, such as CISA, CIA or CRISC is strongly preferred.
- 6+ years of audit, assurance and advisory experience, preferably with a Big 4 or leading risk advisory/ public accounting firm
- Good understanding of IT & Information technology General Controls Frameworks and standards such as ISO, SANS, COBIT, ITIL, COSO and regulations such as SOX, PCI Compliance, HIPAA
- Deep, thorough understanding of technical functions & Comprehensive understanding of cybersecurity trends and threats to the healthcare enterprise
- Demonstrated experience and history of increasing responsibility in project management and supervision in a large, complex information systems environment
- Requires a general knowledge of multiple IT industry best practice frameworks including but not limited to the Information Technology Infrastructure Library (ITIL).
- Experience with the design, development and implementation of internal controls for IT.
- Analytical skills; specifically, the ability to assess and decompose processes utilizing a risk and control focus
- Highly motivated team players who are willing to go the extra mile
- Knowledge of current accounting, auditing principals and internal control concepts
- Exposure or understanding of control concepts and processes with practical experience in regulatory compliance, internal audits, risk management, accounting / process advisory and finance transformation / improvement
- High level of self-confidence, strong people and client management skills and demonstrated leadership ability
- Excellent presentation and written communication skills
- English fluency (written and verbal) is required; fluency in multiple languages is a plus.
- Must have the ability to work in a highly collaborative, team-oriented environment
- Willingness to travel domestically and internationally is required (25-30%)
Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
United States-New Jersey-New Brunswick-
Johnson & Johnson (6067)